Microsoft 365: Block Risky Apps Now
Security
19. Sept 2025 14:15

Microsoft 365: Block Risky Apps Now

von HubSite 365 über Jonathan Edwards

No-Faffing Managed IT Support & Cyber Security Support. Made in Yorkshire, built for the UK.

Secure Microsoft Entra and cloud apps by locking app permissions and enforcing admin consent for stronger Microsoft security

Key insights

  • Application security: Application security in Microsoft 365 is often overlooked but can expose tenant data to shadow IT, data leaks, and malicious apps.
    Controlling app permissions is the fastest way to reduce that risk.
  • User consent vs Admin consent: Users can grant only low-risk permissions, while admins must approve higher‑privilege requests.
    Use this distinction to limit who can give wide access to corporate data.
  • Restrict user consent: Configure settings to allow user consent only for vetted, low-risk apps and block unknown apps.
    This prevents employees from accidentally granting excessive permissions.
  • Admin consent workflow: Enable the admin consent approval process in Microsoft Entra to require IT review before risky permissions are granted.
    Admins then approve, deny, or request more information about each app request.
  • Review applications: Regularly audit existing app registrations and granted permissions and revoke or reduce access for risky apps.
    Prioritize apps that request broad data scopes or uncommon privileges.
  • Best practices: Apply Zero Trust principles, enforce multi-factor authentication, limit app registrations, monitor consent activity, and schedule periodic permission reviews.
    Combine policy controls and continuous review to keep apps secure.

Introduction

Jonathan Edwards’ recent YouTube video, titled Stop Risky Apps Fast, focuses on practical steps to secure applications in Microsoft 365. In the video, he argues that application security inside a tenant is often overlooked and therefore risky for organizations of all sizes. Consequently, his walkthrough aims to give IT teams clear actions to control app permissions and stop users from granting risky access without IT approval.

Moreover, Edwards frames his guidance around a simple promise: reduce accidental or malicious exposure of corporate data by tightening how apps gain permissions. He emphasizes both immediate tactics and longer-term governance improvements. As a result, the audience receives a mix of step-by-step instruction and strategic context.

What the Video Covers

First, Edwards explains the core difference between user consent and admin consent, showing when each type of approval applies and why it matters for risk management. Then, he demonstrates how to locate and evaluate applications through the Microsoft Entra admin interface, which centralizes permission controls. Finally, he walks viewers through configuring restrictions and setting up the admin consent workflow to ensure higher-risk requests receive IT review before approval.

Additionally, Edwards includes a short audit routine that helps teams review existing app permissions and remediate obvious risks. He also provides recommended settings for allowing only vetted low-risk apps while funneling other requests into an approval process. Thus, IT teams can reduce shadow IT and track which apps access corporate data.

Technical Steps and Controls

Edwards demonstrates how to restrict user consent so that only safe, low-privilege apps can obtain access without intervention. He shows how to adjust tenant settings in Microsoft Entra to tighten defaults and minimize broad permission grants. In practice, this means configuring policy to block apps requesting sensitive scopes and allowing users to connect only pre-approved integrations.

Next, he outlines the admin consent workflow, where app requests that need elevated scopes are routed to administrators for review and approval. Edwards recommends defining clear approval criteria and assigning reviewers to avoid bottlenecks. Therefore, teams can balance safety with operational continuity by ensuring legitimate business tools still receive timely access.

Finally, Edwards covers the review of existing application permissions and how to revoke or adjust over-permissive grants. He advises prioritizing high-privilege app reviews and documenting decisions to support audits and compliance. Consequently, organizations can steadily reduce their attack surface without sudden disruption to end users.

Tradeoffs and Operational Challenges

While tightening consent and routing requests through an approval workflow improves security, Edwards acknowledges important tradeoffs between protection and productivity. For instance, strict restrictions may block legitimate tools and frustrate users, which can drive shadow IT if approvals take too long. Therefore, implementing efficient approval paths and communicating clearly with users becomes essential to avoid negative reactions.

In addition, Edwards discusses administrative overhead as a real challenge: reviewers must triage requests and maintain a registry of safe apps, which consumes time and expertise. Smaller IT teams may struggle to sustain thorough reviews without automation or delegated responsibilities. Nonetheless, the alternative—leaving broad permissions unchecked—creates a larger, ongoing security risk.

Moreover, Edwards warns about potential false positives when blocking apps, where well-intentioned services may be flagged as risky due to ambiguous permission descriptions. He recommends combining automated signals with human judgment to reduce unnecessary blocks and to keep business workflows running smoothly. Thus, striking a balance between automated policy and manual oversight is crucial.

Best Practices and Recommendations

As practical next steps, Edwards urges organizations to start with a baseline audit of current app permissions and then apply restrictive defaults. He also suggests categorizing apps by risk level and delegating approval authority for low-risk scenarios to a fast track. In addition, documenting the approval rationale helps with compliance and accelerates repeat decisions.

Furthermore, he ties this approach to a broader security posture, recommending that teams combine app consent controls with multi-factor authentication, endpoint protections, and ongoing user training. Edwards highlights that these measures work best when they operate together under a Zero Trust mindset, where every app and access request is verified. Consequently, a layered approach reduces the chance that a single misconfigured app leads to a serious breach.

Conclusion

Overall, Jonathan Edwards’ video delivers actionable guidance for organizations looking to reduce app-related risks within Microsoft 365. He balances tactical instructions with strategic advice, while also calling out the tradeoffs and operational costs involved in tighter governance. Therefore, teams should plan a staged rollout that pairs restrictive policies with efficient approval processes to maintain productivity while improving security.

Security - Microsoft 365: Block Risky Apps Now

Keywords

Microsoft 365 application security, stop risky apps, third-party app risk management, Azure AD app governance, app permission review Microsoft 365, risky app detection M365, Microsoft Cloud App Security, SaaS app security Microsoft 365